# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=288

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 289

---

## [Filebeat "zeek" module integration](https://discuss.elastic.co/t/filebeat-zeek-module-integration/213598)

<div class="topic-metadata">

**Author:** [@aurquia](https://discuss.elastic.co/u/aurquia)\
**Replies:** 1\
**Last updated:** [January 2, 2020, 6:27pm UTC](https://discuss.elastic.co/t/filebeat-zeek-module-integration/213598 "2020-01-02T18:27:01Z")

</div>

Hello, I've a 7.5.1 Elastic Stack environment (Elasticsearch, Logstash and Kibana running in the same node (zeek master 10.0.2.2)) and another node where is running Filebeat (zeek logger 10.0.2.5). I've followed the st…

---

## [Metricbeat to use EC2 role permissions to access AWS ELK stack](https://discuss.elastic.co/t/metricbeat-to-use-ec2-role-permissions-to-access-aws-elk-stack/213613)

<div class="topic-metadata">

**Author:** [@amanam1203](https://discuss.elastic.co/u/amanam1203)\
**Replies:** 0\
**Last updated:** [January 2, 2020, 6:23pm UTC](https://discuss.elastic.co/t/metricbeat-to-use-ec2-role-permissions-to-access-aws-elk-stack/213613 "2020-01-02T18:23:00Z")

</div>

I installed Metricbeat on a EC2 server to monitor docker containers and configured to send the logs to AWS ELK stack. Metricbeat is not utilizing the role that have permission to access ELK stack. How can i configure Met…

---

## [Resources for newcomers?](https://discuss.elastic.co/t/resources-for-newcomers/213607)

<div class="topic-metadata">

**Author:** [@alexolivan](https://discuss.elastic.co/u/alexolivan)\
**Replies:** 0\
**Last updated:** [January 2, 2020, 5:51pm UTC](https://discuss.elastic.co/t/resources-for-newcomers/213607 "2020-01-02T17:51:20Z")

</div>

Hi forum. Since I succeeded in the past creating (publicly available in github) plugins for real-time monitoring / graphing tools munin and nagios-based Check\_MK/OMD for some popular streaming servers (mostly Icecast2,…

---

## [Icmp monitoring using list file](https://discuss.elastic.co/t/icmp-monitoring-using-list-file/212862)

<div class="topic-metadata">

**Author:** [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Replies:** 4\
**Last updated:** [January 2, 2020, 1:57pm UTC](https://discuss.elastic.co/t/icmp-monitoring-using-list-file/212862 "2020-01-02T13:57:24Z")

</div>

Is it possible to list the icmp monitoring host using list file, because I need to monitor more than 100 IP addresses? If no, is there any workaround to list a lots of hosts in convinient way, let say from csv file? Th…

---

## [Heartbeat get response and exec another request](https://discuss.elastic.co/t/heartbeat-get-response-and-exec-another-request/212571)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 1\
**Last updated:** [January 2, 2020, 1:36pm UTC](https://discuss.elastic.co/t/heartbeat-get-response-and-exec-another-request/212571 "2020-01-02T13:36:06Z")

</div>

Hi, is there a way to instrument a GET operation, check the response body to extract an information and then use it to perform immediately another GET call?

---

## [Filebeat: fail to execute the HTTP GET request](https://discuss.elastic.co/t/filebeat-fail-to-execute-the-http-get-request/213442)

<div class="topic-metadata">

**Author:** [@Robin020](https://discuss.elastic.co/u/Robin020)\
**Replies:** 2\
**Last updated:** [January 2, 2020, 1:31pm UTC](https://discuss.elastic.co/t/filebeat-fail-to-execute-the-http-get-request/213442 "2020-01-02T13:31:17Z")

</div>

Hi, Filebeat wants to do a http get request to http://localhost:5601/api/status but it fails. I am having trouble with configure this on the right way in the filebeat.yml. For Kibana I created a certificate and used t…

---

## [Getting data from three sources to the one metricbeat](https://discuss.elastic.co/t/getting-data-from-three-sources-to-the-one-metricbeat/213577)

<div class="topic-metadata">

**Author:** [@awer1967](https://discuss.elastic.co/u/awer1967)\
**Replies:** 0\
**Last updated:** [January 2, 2020, 1:14pm UTC](https://discuss.elastic.co/t/getting-data-from-three-sources-to-the-one-metricbeat/213577 "2020-01-02T13:14:45Z")

</div>

Hi ! We intend to apply a "performance getting" scheme with metricbeat and logstash for our Vmware environment , consists of three vCenter hosts work independently. We have only one host with Metricbeat installed, whi…

---

## [Cloud.auth setup error](https://discuss.elastic.co/t/cloud-auth-setup-error/213502)

<div class="topic-metadata">

**Author:** [@mxixm](https://discuss.elastic.co/u/mxixm)\
**Replies:** 1\
**Last updated:** [January 2, 2020, 10:40am UTC](https://discuss.elastic.co/t/cloud-auth-setup-error/213502 "2020-01-02T10:40:36Z")

</div>

Good afternoon all, I am trying to configure my logs to go to elastic cloud via winlogbeat. When I run the ".\\winlogbeat.exe setup" command, I get the following error: "Exiting: error loading config file: yaml: line 10…

---

## [Libbeat Elasticsearch default client](https://discuss.elastic.co/t/libbeat-elasticsearch-default-client/213533)

<div class="topic-metadata">

**Author:** [@sashker](https://discuss.elastic.co/u/sashker)\
**Replies:** 0\
**Last updated:** [January 2, 2020, 8:22am UTC](https://discuss.elastic.co/t/libbeat-elasticsearch-default-client/213533 "2020-01-02T08:22:31Z")

</div>

Hello, guys. I'm working with the libbeat and I cannot figure out how I can do something with an ES client which sends events to a server. I need to find a way how I can sign all requests with AWS signature in order to…

---

## [Auditbeat Error : failed to open audit netlink socket: bind failed: operation not permitted](https://discuss.elastic.co/t/auditbeat-error-failed-to-open-audit-netlink-socket-bind-failed-operation-not-permitted/213427)

<div class="topic-metadata">

**Author:** [@irobot678](https://discuss.elastic.co/u/irobot678)\
**Replies:** 0\
**Last updated:** [December 31, 2019, 9:42am UTC](https://discuss.elastic.co/t/auditbeat-error-failed-to-open-audit-netlink-socket-bind-failed-operation-not-permitted/213427 "2019-12-31T09:42:23Z")

</div>

Hi, I'm using ELK stack of version 7.5.1 with x-pack installed and while running auditbeat showing the following error 2020-01-02T12:18:41.065+0530 ERROR instance/beat.go:916 Exiting: 1 error: 1 error: failed to creat…

---

## [Hostname is same for 10 devices , but now in kibana i am able to see one device data only](https://discuss.elastic.co/t/hostname-is-same-for-10-devices-but-now-in-kibana-i-am-able-to-see-one-device-data-only/213473)

<div class="topic-metadata">

**Author:** [@vijaya12](https://discuss.elastic.co/u/vijaya12)\
**Replies:** 0\
**Last updated:** [January 1, 2020, 5:17am UTC](https://discuss.elastic.co/t/hostname-is-same-for-10-devices-but-now-in-kibana-i-am-able-to-see-one-device-data-only/213473 "2020-01-01T05:17:31Z")

</div>

hostname is same for 10 devices , but now in kibana i am able to see one device data only.but 2 metricbeat modules running on 2 different devices. but i am getting only one device data i kibana dashboard

---

## [Filebeat.yml logging issue](https://discuss.elastic.co/t/filebeat-yml-logging-issue/213386)

<div class="topic-metadata">

**Author:** [@RunningSmurf](https://discuss.elastic.co/u/RunningSmurf)\
**Replies:** 2\
**Last updated:** [December 31, 2019, 7:22pm UTC](https://discuss.elastic.co/t/filebeat-yml-logging-issue/213386 "2019-12-31T19:22:12Z")

</div>

Hello, I noticed that my filebeat beat was not producing a log file. I realized that I never set a filename, path, etc... I set the following, but I get the following error with the file path: Any suggestion would …

---

## [Metricbeat Storage in ElasticSearch index](https://discuss.elastic.co/t/metricbeat-storage-in-elasticsearch-index/213212)

<div class="topic-metadata">

**Author:** [@benjamin.watson](https://discuss.elastic.co/u/benjamin.watson)\
**Replies:** 1\
**Last updated:** [December 31, 2019, 3:32pm UTC](https://discuss.elastic.co/t/metricbeat-storage-in-elasticsearch-index/213212 "2019-12-31T15:32:38Z")

</div>

Greetings all, I'm designing a monitoring and alerting platform and intend to base it largely on ElasticSearch and leverage Metricbeat for per host metrics collection. I've looked up some general (and often conflicting…

---

## [Metricbeat autodiscover hints for MySQL](https://discuss.elastic.co/t/metricbeat-autodiscover-hints-for-mysql/211575)

<div class="topic-metadata">

**Author:** [@stingus](https://discuss.elastic.co/u/stingus)\
**Replies:** 5\
**Last updated:** [December 31, 2019, 10:33am UTC](https://discuss.elastic.co/t/metricbeat-autodiscover-hints-for-mysql/211575 "2019-12-31T10:33:09Z")

</div>

I'm looking for a way to setup auto-discovery based on docker hints for MySQL, as described here: https://www.elastic.co/guide/en/beats/metricbeat/current/configuration-autodiscover-hints.html How can I set the MySQL us…

---

## [Indentation issue with apache module ( Filebeat 7.5 )](https://discuss.elastic.co/t/indentation-issue-with-apache-module-filebeat-7-5/213435)

<div class="topic-metadata">

**Author:** [@IneedHelp](https://discuss.elastic.co/u/IneedHelp)\
**Replies:** 0\
**Last updated:** [December 31, 2019, 10:25am UTC](https://discuss.elastic.co/t/indentation-issue-with-apache-module-filebeat-7-5/213435 "2019-12-31T10:25:04Z")

</div>

Hello, I have a problem with the apache module of filebeat ( version 7.5). I followed the next tutorial : Apache module | Filebeat Reference \[8.11\] | Elastic but when i execute filebeat, filebeat returns this error : E…

---

## [Shipping gitlab job logs](https://discuss.elastic.co/t/shipping-gitlab-job-logs/213005)

<div class="topic-metadata">

**Author:** [@meir](https://discuss.elastic.co/u/meir)\
**Replies:** 4\
**Last updated:** [December 31, 2019, 7:54am UTC](https://discuss.elastic.co/t/shipping-gitlab-job-logs/213005 "2019-12-31T07:54:23Z")

</div>

HI, I have started using filebeat for log shipping for my gitlab logs, and I have a directory structure that is changed every few minutes, each directory contains a log file which contains data that I want to ship to my…

---

## [Getting error unpacking config data: more than one namespace configured accessing 'output' (source:'/usr/local/etc/filebeat/filebeat.yml')](https://discuss.elastic.co/t/getting-error-unpacking-config-data-more-than-one-namespace-configured-accessing-output-source-usr-local-etc-filebeat-filebeat-yml/213346)

<div class="topic-metadata">

**Author:** [@sakshi1234](https://discuss.elastic.co/u/sakshi1234)\
**Replies:** 2\
**Last updated:** [December 31, 2019, 6:19am UTC](https://discuss.elastic.co/t/getting-error-unpacking-config-data-more-than-one-namespace-configured-accessing-output-source-usr-local-etc-filebeat-filebeat-yml/213346 "2019-12-31T06:19:27Z")

</div>

Hi, When i am running below command: filebeat modules enable logstash i m getting unpacking config data: more than one namespace configured accessing 'output' (source:'/usr/local/etc/filebeat/filebeat.yml') Can some…

---

## [How to send an application (systemd service) logs to Logstash using Journalbeat?](https://discuss.elastic.co/t/how-to-send-an-application-systemd-service-logs-to-logstash-using-journalbeat/212435)

<div class="topic-metadata">

**Author:** [@arblr](https://discuss.elastic.co/u/arblr)\
**Replies:** 2\
**Last updated:** [December 31, 2019, 6:04am UTC](https://discuss.elastic.co/t/how-to-send-an-application-systemd-service-logs-to-logstash-using-journalbeat/212435 "2019-12-31T06:04:35Z")

</div>

My application / service name 'appdb', running as systemd service. I can observe logs from this application using shall command 'journalctl -u appdb.service'. I want to send these logs to Logstash. I am using the followi…

---

## [Send data in seperate lines from beats](https://discuss.elastic.co/t/send-data-in-seperate-lines-from-beats/210169)

<div class="topic-metadata">

**Author:** [@Saravana37](https://discuss.elastic.co/u/Saravana37)\
**Replies:** 5\
**Last updated:** [December 17, 2019, 12:30pm UTC](https://discuss.elastic.co/t/send-data-in-seperate-lines-from-beats/210169 "2019-12-17T12:30:41Z")

</div>

Hi , We are configuring Siebel app server monitoring and we are running a batch file in execbeat . our output looks like below . Siebel Enterprise Applications Siebel Server Manager, Version 16.19.0.0 \[23057\] LANG\_IND…

---

## [Metricbeat L](https://discuss.elastic.co/t/metricbeat-l/213181)

<div class="topic-metadata">

**Author:** [@Lucas\_Hyuck\_Joo](https://discuss.elastic.co/u/Lucas_Hyuck_Joo)\
**Replies:** 1\
**Last updated:** [December 30, 2019, 6:08pm UTC](https://discuss.elastic.co/t/metricbeat-l/213181 "2019-12-30T18:08:34Z")

</div>

Hi, My teams are trying to get statistics on network In/Out traffic from CentOS 7.3. I've tried get but it doesn't know Sometimes a several network metircs are lost and I can't see in Grafana. I am wondering if ther…

---

## [Filebeat include\_lines issue](https://discuss.elastic.co/t/filebeat-include-lines-issue/213211)

<div class="topic-metadata">

**Author:** [@RunningSmurf](https://discuss.elastic.co/u/RunningSmurf)\
**Replies:** 3\
**Last updated:** [December 30, 2019, 9:12pm UTC](https://discuss.elastic.co/t/filebeat-include-lines-issue/213211 "2019-12-30T21:12:39Z")

</div>

Hello, I have Filebeat installed on a Windows server. I configured it to read logs from SQL Server. I can see that all lines are individually passed to ES, as I can see them in Kibana. My goal is to only send the lin…

---

## [Filebeat error connecting to Elasticsearch](https://discuss.elastic.co/t/filebeat-error-connecting-to-elasticsearch/213079)

<div class="topic-metadata">

**Author:** [@JY\_DT](https://discuss.elastic.co/u/JY_DT)\
**Replies:** 6\
**Last updated:** [December 30, 2019, 8:04pm UTC](https://discuss.elastic.co/t/filebeat-error-connecting-to-elasticsearch/213079 "2019-12-30T20:04:06Z")

</div>

I have Filebeat on a Windows 10 machine sending log data to Elasticsearch on a Windows Server 2016. The services are running correctly. As I'd posted earlier, I'm using basic authentication. I've created a user named fi…

---

## [Filebeat - service should automatically starts](https://discuss.elastic.co/t/filebeat-service-should-automatically-starts/213057)

<div class="topic-metadata">

**Author:** [@aolvikash](https://discuss.elastic.co/u/aolvikash)\
**Replies:** 3\
**Last updated:** [December 30, 2019, 7:59pm UTC](https://discuss.elastic.co/t/filebeat-service-should-automatically-starts/213057 "2019-12-30T19:59:31Z")

</div>

Hi, I have the filebeat running on Freebsd and started the filebeat service via "service filebeat onestart" however I want to run filebeat service automatically in case service has stopped or if the server is rebooted, …

---

## [Empty lines in multiline pattern(python error traceback) in filebeat input are not getting parsed correctly?](https://discuss.elastic.co/t/empty-lines-in-multiline-pattern-python-error-traceback-in-filebeat-input-are-not-getting-parsed-correctly/213355)

<div class="topic-metadata">

**Author:** [@Jaaved\_Ali\_Khan](https://discuss.elastic.co/u/Jaaved_Ali_Khan)\
**Replies:** 1\
**Last updated:** [December 30, 2019, 1:50pm UTC](https://discuss.elastic.co/t/empty-lines-in-multiline-pattern-python-error-traceback-in-filebeat-input-are-not-getting-parsed-correctly/213355 "2019-12-30T13:50:36Z")

</div>

The log line which should be harvested and published to logstash as a single line: \[pid: 17318|app: 0|req: 1/2\] 10.14.206.28 (jaavedkhan) {60 vars in 1296 bytes} \[Mon Dec 30 15:51:38 2019\] GET /en/ =\> generated 27 bytes…

---

## [Filebeat indices get grouped by ILM](https://discuss.elastic.co/t/filebeat-indices-get-grouped-by-ilm/210144)

<div class="topic-metadata">

**Author:** [@stk1](https://discuss.elastic.co/u/stk1)\
**Replies:** 3\
**Last updated:** [December 29, 2019, 2:16pm UTC](https://discuss.elastic.co/t/filebeat-indices-get-grouped-by-ilm/210144 "2019-12-29T14:16:36Z")

</div>

Hi, my Problem is that Filebeat indices are not named like the default should be (on a daily basis), but the naming seems to be affected by the used Index Lifecycle Policy. So when they should stay in hot phase for 6 da…

---

## [Heartbeat not writing to log file](https://discuss.elastic.co/t/heartbeat-not-writing-to-log-file/213213)

<div class="topic-metadata">

**Author:** [@yodog](https://discuss.elastic.co/u/yodog)\
**Replies:** 0\
**Last updated:** [December 27, 2019, 5:09pm UTC](https://discuss.elastic.co/t/heartbeat-not-writing-to-log-file/213213 "2019-12-27T17:09:44Z")

</div>

heartbeat is not writing to log file. i know it is loging to journal, because this works: journalctl -u heartbeat-elastic Dez 27 14:04:15 elastic-zmb-01 systemd\[1\]: Started Ping remote services for availability and lo…

---

## [Basic Apache Filebeat Log question - missing fields](https://discuss.elastic.co/t/basic-apache-filebeat-log-question-missing-fields/213103)

<div class="topic-metadata">

**Author:** [@Shorthills](https://discuss.elastic.co/u/Shorthills)\
**Replies:** 8\
**Last updated:** [December 27, 2019, 4:10pm UTC](https://discuss.elastic.co/t/basic-apache-filebeat-log-question-missing-fields/213103 "2019-12-27T16:10:02Z")

</div>

Hi, Sorry for the newbie question: I'm able to pull in my apache logs and when I try to filter by apache2.access.response\_code , I get zilch. I looked and the response code data is in the message from apache. Is the p…

---

## [Filebeat Startup problem](https://discuss.elastic.co/t/filebeat-startup-problem/213168)

<div class="topic-metadata">

**Author:** [@Gregory\_Anne](https://discuss.elastic.co/u/Gregory_Anne)\
**Replies:** 2\
**Last updated:** [December 27, 2019, 12:51pm UTC](https://discuss.elastic.co/t/filebeat-startup-problem/213168 "2019-12-27T12:51:49Z")

</div>

Hello Env description : I have a cluster of two nodes with a Jetty app. The application generate log on the file /var/log/jetty/jetty.log The log rotation is handle by logrotate avery day at 6:30. On both I run file…

---

## [Filebeat 7.2 for RHEL 5.1: init file changes](https://discuss.elastic.co/t/filebeat-7-2-for-rhel-5-1-init-file-changes/213175)

<div class="topic-metadata">

**Author:** [@katara](https://discuss.elastic.co/u/katara)\
**Replies:** 0\
**Last updated:** [December 27, 2019, 10:18am UTC](https://discuss.elastic.co/t/filebeat-7-2-for-rhel-5-1-init-file-changes/213175 "2019-12-27T10:18:50Z")

</div>

Hi, I am currently trying to install filebeat 7.2 on an RHEL 5.1. I am aware Filebeat doesnt support RHEL 5. But I read the possibility after hacking the init file to not use the god parts in the below answer: filebe…

---

## [Filebeat registry (inode) clean case restart slow](https://discuss.elastic.co/t/filebeat-registry-inode-clean-case-restart-slow/213116)

<div class="topic-metadata">

**Author:** [@john\_am](https://discuss.elastic.co/u/john_am)\
**Replies:** 0\
**Last updated:** [December 27, 2019, 1:52am UTC](https://discuss.elastic.co/t/filebeat-registry-inode-clean-case-restart-slow/213116 "2019-12-27T01:52:22Z")

</div>

1 What's go on? Filebeat terrible slow to start harvest after I configure the inode clean. 2 My config are as follow: \</\> type: log enabled: true paths: /data/aaa/aaa/\*\* tags: \["aaa"\] fields: public\_ip: 14.1…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=287)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=289)
